8

CVSS3.1

CVE-2025-22960 -

A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially revealing sensitive session-related information such as session IDs (sess_id) and auth…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-56908 -

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directo…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-57782 -

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-53309 -

A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via speciall…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-25354 -

A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Feb. 14, 2025, 7:39 p.m.

9.8

CVSS3.1

CVE-2025-25389 -

A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 7:04 p.m.

7.8

CVSS3.1

CVE-2025-21700 - net: sched: Disallow replacing of child qdisc from one parent to another

In the Linux kernel, the following vulnerability has been resolved: net: sched: Disallow replacing of child qdisc from one parent to another Lion Ackermann was able to create a UAF which can be abused for privilege escalation with the following script Step 1. create root qdisc tc qdisc add dev l…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 8:39 a.m.

7.2

CVSS3.1

CVE-2025-25352 -

A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Feb. 14, 2025, 7:43 p.m.

7.5

CVSS3.1

CVE-2025-25897 -

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 4:15 p.m.

7.2

CVSS3.1

CVE-2025-22962 -

A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json endpoint, enabling arbitra…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348395
Page 6668 of 34,840
Β« previous page Β» next page
Filters